[NT] IBM DB2 Remote Command Execution Privilege Escalation

From: SecuriTeam (support_at_securiteam.com)
Date: 03/10/04

  • Next message: SecuriTeam: "[NEWS] PWebServer Directory Traversal Vulnerability"
    To: list@securiteam.com
    Date: 10 Mar 2004 19:25:26 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      IBM DB2 Remote Command Execution Privilege Escalation
    ------------------------------------------------------------------------

    SUMMARY

    IBM's DB2 is the market share leader for database server software. One of
    the components, the Remote Command Server, contains a vulnerability that
    can allow attackers to gain administrative privileges on the server
    running DB2.

    DETAILS

    Vulnerable Systems:
     * DB2 version 8.1 Enterprise Edition on Windows

    DB2 with the Remote Command Server, DB2RCMD.EXE, listens on a named pipe
    DB2REMOTECMD and executes commands sent through it. When a connection is
    made to the pipe a new process is created, namely db2rcmdc.exe, and this
    executes the command. Whilst a valid Windows user id and password are
    required the command executes with the privileges of the "db2admin"
    account which is an administrator.

    This essentially means that even a low privileged "Guest" account can run
    commands remotely with administrative privileges. This can lead to a
    compromise of the server running DB2.

    Fix Information:
    IDM have included a fix for this problem in Fixpak 5 -
    <http://www-306.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/v8fphist.d2w/report> http://www-306.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/v8fphist.d2w/report.

    The APAR for this specific issue is IY53894 -
    <http://www-306.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/aparlib.d2w/display_apar_details?aparno=IY53894> http://www-306.ibm.com/cgi-bin/db2www/data/db2/udb/winos2unix/support/aparlib.d2w/display_apar_details?aparno=IY53894.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:nisr@nextgenss.com>
    NGSSoftware Insight Security Research.

    The original article can be found at:
    <http://www.ngssoftware.com/advisories/db2rmtcmd.txt>
    http://www.ngssoftware.com/advisories/db2rmtcmd.txt

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NEWS] PWebServer Directory Traversal Vulnerability"

    Relevant Pages

    • [UNIX] OpenBB Multiple Vulnerabilities (board.php, search.php, member.php, post.php, myhome.php, ind
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... arbitrary command execution. ... snippet of code from one of the vulnerable scripts is presented ...
      (Securiteam)
    • [EXPL] I-Mall Commerce i-mall.cgi Arbitrary Command Execution (Exploit)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A remote command execution vulnerability has been discovered in the I-Mall ... sub intro { ... chomp $host; ...
      (Securiteam)
    • [UNIX] Lukemftpd (Tnftpd) Multiple Vulnerabilities May Lead To Remote Code Execution
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... structure tab to indicate if it's acceptable for a command to occur in OOB ... delivering of ABOR and STAT commands in OOB mode. ...
      (Securiteam)
    • [UNIX] Sudo Race Condition Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A race condition with the Sudo command pathname handling allows a local ... When a user runs a command via Sudo, the inode and device numbers of the ... listed in the sudoers file is stored in the variable safe_cmnd, ...
      (Securiteam)
    • [NEWS] payShield Library Bad Requests Verification
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... When a command is sent through the SPP library the library may query its ... Although an error message will be printed to the payShield log this error ... There is a work-around to this problem, but it is more intrusive than ...
      (Securiteam)